Spencer McIntyre
06d1165a8b
Remove dead code in the auxiliary/gather/enum_dns option
2020-10-30 10:45:08 -04:00
Grant Willcox
4479f4f0e1
Update library and module to fully support version 5.2. Also update the module to support guest discovery on newer versions on Zabbix
2020-10-29 19:27:12 -05:00
h00die
238889282a
module cleanup
2020-10-29 17:11:19 -04:00
h00die
c4e74c2ed0
wip chopslider
2020-10-29 15:33:37 -04:00
h00die
f94acb94c9
cleanup
2020-10-29 10:46:14 -04:00
Spencer McIntyre
861879275e
Land #14250 , Fix how DNS enumeration displays AXFR results
2020-10-28 13:38:38 -04:00
Grant Willcox
85c3058e7d
Delete the unused axfr function from auxiliary/gather/enum_dns
2020-10-28 09:34:13 -05:00
h00die
0abdaf9f67
WIP
2020-10-27 21:30:46 -04:00
h00die
c11d07aed2
more cleanup
2020-10-27 17:53:30 -04:00
h00die
9c3b62f071
sqli help needed
2020-10-27 12:09:22 -04:00
Niboucha Redouane
17c7c4fdbe
Fix issues
2020-10-27 00:55:06 +01:00
Grant Willcox
bd57832494
First round of changes from review
2020-10-26 16:02:06 -05:00
Spencer McIntyre
291c883db8
Don't alter the os_name or os_flavor keys in report_host
2020-10-23 09:48:33 -04:00
Spencer McIntyre
3fdeb1933d
Report the host details when scanning for MS17-010
2020-10-22 17:45:37 -04:00
Spencer McIntyre
2077f241c1
Support and use CheckCode details to share relevant information
...
Modules that can be used as check modules should be able to share
information with their exploit counterpart.
2020-10-21 16:29:31 -04:00
h00die
f3a633b89e
cve-2018-14847
2020-10-18 11:13:16 -04:00
h00die
252a5ace25
winbox_fileread
2020-10-17 13:12:25 -04:00
Karn Ganeshen
9a148bcaf4
new updates to module
...
added nil response and good response case, target hostname, and os details are now captured in hosts and services db, some cosmetics, fixed date format, and timeout handling.
2020-10-16 03:17:12 +05:30
Karn Ganeshen
262b51a659
Apache Zookeeper Information Disclosure
...
Adding new module for Zookeeper info disclosure
2020-10-15 16:54:38 +05:30
Faiz Azhar
193d15381e
Cloudflare (NYSE:NET) is an independent company and unrelated to Amazon (NASDAQ: AMZN)
2020-10-10 00:13:43 +08:00
Grant Willcox
7cc9d663dc
Land #14242 , Remove modules whose deprecation date has past
2020-10-08 11:34:00 -05:00
Spencer McIntyre
3431d97c64
Remove modules whose deprecation date has past
2020-10-08 10:56:37 -04:00
Vladimir Ivanov
d2ee5a838a
Update sap_service_discovery.rb
...
Add port 40080 - SAP Internet Graphics Server [HTTP]
2020-10-08 13:51:44 +03:00
Grant Willcox
a2675c13e8
Land #14213 , Add disclosure date rubocop linting rule - enforce iso8601 disclosure dates
2020-10-07 12:09:59 -05:00
Ivanov Vladimir
fa7b711d60
Change ltype in loot
2020-10-07 10:12:09 -05:00
Grant Willcox
12095f9174
Make minor updates to the error messages
2020-10-07 10:12:09 -05:00
Ivanov Vladimir
df86b0c7c2
Update script to ensure action_file_read will correctly use fail_with, and to update the return types of send_first_request.
2020-10-07 10:11:12 -05:00
Grant Willcox
5ad2190c40
Apply updates to the module from the review process and a minor update to the documentation to note the renaming of the PATH option to URIPATH. Also update the check method so that it now works correctly and so that other functions return errors appropriately.
2020-10-07 10:08:57 -05:00
Ivanov Vladimir
cc721fd64f
Update several functions to apply review edits and also update the documentation accordingly.
2020-10-07 10:07:48 -05:00
Ivanov Vladimir
9ce3dc45f7
Delete default option: VERBOSE
2020-10-07 10:07:46 -05:00
Ivanov Vladimir
24d14f8816
Rename URN to PATH in several functions. Also change check function.
2020-10-07 10:04:55 -05:00
Grant Willcox
8a8dfafcc3
Rename the files and update some descriptions as there may be more XXE bugs in SAP in the future. Also update the documentation accordingly.
2020-10-07 10:04:03 -05:00
Grant Willcox
fc462d2465
Clean up code to remove some extra options and to make the match() calls a bit cleaner, as well as make some of the explanations a bit neater. Also remove duplicate code from a few places
2020-10-07 10:04:02 -05:00
Grant Willcox
a70cb25824
Remove all verbose options and tidy up one extra instance variable that was only used once
2020-10-07 10:04:02 -05:00
Vladimir Ivanov
7c682af98b
Create sap_igs_xxe.rb and its associated documentation, and apply RuboCop fixes.
2020-10-07 10:03:09 -05:00
Alan Foster
30809787c4
Convert disclosure dates to iso8601
2020-10-02 21:00:37 +01:00
Alan Foster
26ff912291
Fix invalid disclosure date formats
2020-10-02 12:20:05 +01:00
Spencer McIntyre
bf13ffc692
Update documentation based on feedback
2020-10-01 09:19:15 -04:00
Christophe De La Fuente
94796f5c91
Updates from review #2
2020-09-30 15:01:54 +02:00
Spencer McIntyre
d53da9a83a
Always show the plain password value of the machine account
2020-09-29 16:17:02 -04:00
Spencer McIntyre
d91a9a0468
Consolidate the aes_cts_hmac_sha1_96_key functions
2020-09-29 16:05:06 -04:00
Christophe De La Fuente
67821e32c4
Password cracking integration
2020-09-29 20:36:39 +02:00
Christophe De La Fuente
9cb419ae8c
Resync with master branch
2020-09-28 15:45:02 +02:00
Christophe De La Fuente
59fff3d7fe
Land #14161 , VyOS config processor
2020-09-28 13:02:19 +02:00
Grant Willcox
1710b98ba4
Land #14173 , Unify the socks modules using a VERSION option
2020-09-22 17:09:34 -05:00
Spencer McIntyre
a14780d024
Update the zerologon options for clarity
2020-09-22 14:57:57 -04:00
Spencer McIntyre
a67379d1e1
Fix rubocop complaints
2020-09-22 10:28:58 -04:00
Spencer McIntyre
77f0d90bf0
Unify the socks modules using a VERSION option
2020-09-22 10:16:00 -04:00
Spencer McIntyre
3ae4eb3dce
Convert the BinData error_status value to a Ruby integer
2020-09-21 11:38:33 -04:00
h00die
610d4d86d2
initial vyos implementation
2020-09-20 19:48:20 -04:00